<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510, Access other interface problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167290#M875968</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A host residing on an interface can only ping its adjacnet ASA interface.It cannot ping  the far end&lt;/P&gt;&lt;P&gt;interface of ASA. For example if you have a host on inside, this host can only ping the&lt;/P&gt;&lt;P&gt;inside interface of ASA and no other interface (eg: outside or dmz). Although the Hosts connected to "Far end interfaces" can be pinged, "Far end interface" cannot be pinged by a host . This is a security feature on ASA firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Feb 2009 08:11:32 GMT</pubDate>
    <dc:creator>Syed Iftekhar Ahmed</dc:creator>
    <dc:date>2009-02-23T08:11:32Z</dc:date>
    <item>
      <title>ASA 5510, Access other interface problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167288#M875966</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have just configured my brand new ASA 5510 with ASA Version 8.0(4). i am having a little problem that is: i cannot access(nor even ping) DMZ interface and other interface from Inside Host, mean while i can access the servers behind DMZ and other interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i ping to DMZ interface i found the below msgs in logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Built inbound ICMP connection for faddr 192.168.10.33/512 gaddr 172.16.250.5/0 laddr 172.16.250.5/0&lt;/P&gt;&lt;P&gt;Details:&lt;/P&gt;&lt;P&gt;% ASA-6-302020: Built {in | out}bound ICMP connection for faddr {faddr | icmp_seq_num} gaddr {gaddr | cmp_type} laddr laddr&lt;/P&gt;&lt;P&gt;An ICMP session was established in the fast-path when stateful ICMP is enabled using the inspect icmp command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown ICMP connection for faddr 192.168.10.33/512 gaddr 172.16.250.5/0 laddr 172.16.250.5/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;details:&lt;/P&gt;&lt;P&gt;%ASA-6-302021: Teardown ICMP connection for faddr {faddr | icmp_seq_num} &lt;/P&gt;&lt;P&gt;gaddr {gaddr | cmp_type} laddr laddr&lt;/P&gt;&lt;P&gt;An ICMP session was removed in the fast-path when stateful ICMP is enabled using the inspect icmp command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i tried alot but couldnt get success.&lt;/P&gt;&lt;P&gt;please help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167288#M875966</guid>
      <dc:creator>zafar12233</dc:creator>
      <dc:date>2019-03-11T14:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, Access other interface problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167289#M875967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A host residing on an interface can only ping its adjacnet ASA interface.It cannot ping  the far end&lt;/P&gt;&lt;P&gt;interface of ASA. For example if you have a host on inside, this host can only ping the&lt;/P&gt;&lt;P&gt;inside interface of ASA and no other interface (eg: outside or dmz). Although the Hosts connected to "Far end interfaces" can be pinged, "Far end interface" cannot be pinged by a host . This is a security feature on ASA firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 08:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167289#M875967</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2009-02-23T08:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, Access other interface problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167290#M875968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A host residing on an interface can only ping its adjacnet ASA interface.It cannot ping  the far end&lt;/P&gt;&lt;P&gt;interface of ASA. For example if you have a host on inside, this host can only ping the&lt;/P&gt;&lt;P&gt;inside interface of ASA and no other interface (eg: outside or dmz). Although the Hosts connected to "Far end interfaces" can be pinged, "Far end interface" cannot be pinged by a host . This is a security feature on ASA firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 08:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167290#M875968</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2009-02-23T08:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, Access other interface problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167291#M875969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you So Much for your Reply Mr. Iftikhar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got your point, i sensed that too, but wasnt sure, once again thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;i have a question that this security feature is only available in ASA ver. 8.0(4) or its ASA feature regardless of ASA Version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Zafar-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 09:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167291#M875969</guid>
      <dc:creator>zafar12233</dc:creator>
      <dc:date>2009-02-23T09:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, Access other interface problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167292#M875970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its there since PIX days.&lt;/P&gt;&lt;P&gt;Its exists for all ASA codes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 09:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167292#M875970</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2009-02-23T09:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, Access other interface problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167293#M875971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks once again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 10:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-other-interface-problem/m-p/1167293#M875971</guid>
      <dc:creator>zafar12233</dc:creator>
      <dc:date>2009-02-23T10:19:11Z</dc:date>
    </item>
  </channel>
</rss>

